Privacy Policy
Effective: 4 September 2026 · Last updated: 4 September 2026
Draft pending legal review. This document was prepared to describe accurately what the PathForward Financial application actually does with your data, based on a technical audit of the software. It has not yet been reviewed by an attorney. If you are the operator of this service, have counsel review it before launch.
PathForward Financial (“PathForward”, “we”, “us”) provides personal budgeting and financial planning software. This policy explains what information we collect, why, who else can see it, how long we keep it, and how you can get it deleted.
We are not a bank, a lender, a broker-dealer, or a registered investment adviser. We do not sell your personal information, and we do not sell or share your financial account data with advertisers.
1. Information we collect
Information you give us
- Account details — your email address, and your display name and profile photo if you provide them. If you sign in with Google, we receive your email address, name, and profile photo from Google.
- Profile information — optionally your date of birth, gender, marital status, occupation, and state of residence. All of these are optional and the app works without them.
- Financial information you enter — income, expenses, bills, debts and balances, interest rates, savings goals, assets, liabilities, property values, and any notes or motivations you write into the app.
Information from your bank, if you connect one
Connecting a bank account is entirely optional and is a paid feature. If you choose to connect one, we use Plaid Inc. to establish that connection. Through Plaid we receive:
- Account names, types, and balances.
- Transaction history — dates, amounts, descriptions, and merchant categories.
We never see or store your bank username or password. You enter those directly with Plaid, and they are not transmitted to us. Plaid gives us an access credential that is stored on our servers and is never sent to your browser or to any other party. Plaid’s own privacy practices are described at plaid.com/legal.
Information from payment processing
If you subscribe, payment is handled entirely by Stripe, Inc. We do not receive or store your full card number. We receive and store a Stripe customer identifier, your subscription status and renewal date, and the state or region from your billing address.
Information collected automatically
- Local browser storage. The application stores data in your browser to keep your work between visits and remember preferences such as light or dark mode. This can include values you have typed into forms. It stays on your device.
- Sign-in metadata — account creation time and most recent sign-in time, provided by Firebase Authentication.
- Server logs — standard operational logs from Google Cloud, which may include IP addresses and error diagnostics.
We do not use advertising cookies, tracking pixels, or third-party analytics that follow you across other websites.
2. How we use your information
- To provide the service — calculating budgets, projections, debt payoff plans, and net worth.
- To authenticate you and keep your account secure.
- To process subscription payments and manage your plan.
- To synchronise transactions from a bank account you have connected.
- To respond to support requests.
- To understand aggregate usage — how many people have signed up, and in which states — in a form that does not identify individuals.
We do not use your financial data to train machine-learning models, and we do not sell it.
3. Who else can see your data
Service providers
| Provider | Purpose | What they receive |
|---|---|---|
| Google Firebase / Google Cloud | Hosting, authentication, database, file storage | All account and application data |
| Plaid Inc. | Bank connections | Your bank credentials (directly, never via us) and account data |
| Stripe, Inc. | Subscription payments | Payment details, billing address, email |
| RentCast | Optional home value estimates | Only a property address and postcode you explicitly submit |
People you invite
If you use household sharing to invite another person into your budget, that person can read and change your budget data, including income, expenses, debts, savings, and any synced bank transactions. Only invite someone you intend to share your full financial picture with. You can end the arrangement at any time from Settings.
Administrators
Our staff can view account-level records — email address, plan, subscription status, sign-in dates, and state — in order to provide support and operate the service. Every administrative action is written to a permanent audit log. Staff access is limited by role, and the ability to change roles or delete accounts is restricted to the service owner.
Legal
We may disclose information if required by law, or where necessary to investigate fraud or protect the safety of a person. If we are ever acquired or merge with another company, your information may transfer as part of that transaction; we will tell you before it becomes subject to a different privacy policy.
4. How long we keep it, and how to delete it
We keep your information for as long as your account is open. You can delete your account at any time from Settings → Account. When you do, we:
- Cancel any active subscription.
- Disconnect and revoke every linked bank connection with Plaid.
- Delete your budget, transaction history, savings goals, snapshots, and uploaded profile photo.
- Delete your sign-in account.
Deletion completes within 30 days. Two things survive it, deliberately:
- Administrative audit records — a log of actions taken on accounts by staff. These are retained for accountability and cannot be edited or removed by anyone, including us.
- Records we are legally required to keep, such as payment and tax records held by Stripe.
5. Your rights
Depending on where you live — including under the California Consumer Privacy Act and the EU/UK General Data Protection Regulation — you may have the right to:
- Know what personal information we hold about you.
- Get a copy of it. The app provides CSV export of your budget, transactions, and net worth history.
- Correct information that is wrong.
- Delete your information.
- Withdraw consent for bank syncing by disconnecting the connection.
- Not be discriminated against for exercising any of these rights.
We do not sell personal information and have not done so in the preceding twelve months.
To exercise a right, email pathforward.financial.2026@gmail.com. We will respond within 30 days and may need to verify your identity first.
6. Security
We protect your data with access rules that restrict every record to its owner, encryption in transit, credentials held in a dedicated secrets manager rather than in code, server-side enforcement of every permission, and an append-only audit log of administrative actions. Bank access credentials are stored only on our servers and are never sent to a browser.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by law.
7. Children
PathForward is not intended for anyone under 18. We do not knowingly collect information from children. If you believe a child has given us information, contact us and we will delete it.
8. Changes to this policy
If we make a material change, we will update the date at the top of this page and notify you in the application or by email before it takes effect. Continuing to use the service after a change means you accept the updated policy.
9. Contact
Questions about this policy or your data:
pathforward.financial.2026@gmail.com